The Cyber Security Authority (CSA) has slapped Ernst & Young (EY) Ghana with an administrative penalty of GH¢360,000 for providing regulated cybersecurity services without a valid Cybersecurity Service Provider (CSP) licence.

The sanction follows EY Ghana’s continued provision of regulated cybersecurity services, including services to owners of Critical Information Infrastructure (CII), despite directives from the CSA to comply with Ghana’s cybersecurity licensing requirements.
In a statement dated August 18, 2026, the CSA said it had directed EY Ghana in a letter dated March 20, 2026, to apply for a CSP licence within 15 days.
However, the Authority said the company failed to comply with three separate regulatory directives issued to it.
According to the CSA, the breaches contravened Sections 49 and 92 of the Cybersecurity Act, 2020 (Act 1038), which prohibit the provision of regulated cybersecurity services without the required licence and provide sanctions for failure to comply with directives issued by the Authority.
The CSA said it imposed 10,000 penalty units, equivalent to GH¢120,000, for each of the three instances of non-compliance under Sections 49(2), 92(2) and 93 of the Act.
The three penalties bring the total administrative sanction against EY Ghana to GH¢360,000.
The company has been directed to pay the penalty within 14 calendar days from the date of the final enforcement directive.
In addition to the financial penalty, the CSA has issued an immediate cease-and-desist order against EY Ghana, directing the company to stop providing all regulated cybersecurity services without the requisite licence.
The order covers Governance, Risk and Compliance (GRC) services among other regulated cybersecurity activities.
EY Ghana has also been directed to submit written confirmation to the CSA that the affected services have been discontinued and to complete the process of applying for a CSP licence.
The Authority stressed that merely submitting an application does not authorise an entity to operate as a licensed Cybersecurity Service Provider.
It said organisations must first obtain the requisite licence before commencing regulated cybersecurity services.
CSA Warns Unlicensed Cybersecurity Providers
The CSA said the enforcement action against EY Ghana should serve as a warning to organisations and professionals providing regulated cybersecurity services without the required licence.
The Authority particularly stressed the importance of compliance where cybersecurity services are provided to owners of Critical Information Infrastructure, whose security and resilience are considered essential to Ghana’s national security, economy and delivery of critical services.
The CSA noted that the size, reputation, expertise or clientele of a service provider does not exempt it from Ghana’s cybersecurity laws.
It maintained that all Cybersecurity Service Providers operating in Ghana are subject to the same regulatory requirements under the Cybersecurity Act, 2020 (Act 1038), as well as directives issued by the Authority.
The CSA has therefore directed all organisations and professionals providing regulated cybersecurity services without a valid licence to immediately stop such activities and regularise their operations.
The Authority warned that it will continue monitoring compliance and take enforcement action against institutions that engage unlicensed providers and entities that offer regulated cybersecurity services without the required licence.
Such enforcement measures could include administrative sanctions, court proceedings and, where permitted by law, the publication of the names of unlicensed service providers.
The CSA also urged organisations, particularly owners of Critical Information Infrastructure, to obtain cybersecurity services only from appropriately licensed providers.
It stressed that cybersecurity licensing is a legal requirement and not merely an administrative formality.
The Authority said it would continue to use its regulatory powers to protect Ghana’s digital ecosystem and ensure that organisations responsible for critical systems and sensitive information comply with their cybersecurity obligations.










































